> ## Content Index
> Fetch the complete content index at: https://www.cybrsecmedia.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# AI Is Moving Faster Than Enterprise Security. Organizations Are Spending to Catch Up
- URL: https://www.cybrsecmedia.com/ai-is-moving-faster-than-enterprise-security-organizations-are-spending-to-catch-up/
- Published: 2026-10-02T20:25:58.000Z
- Updated: 2026-10-02T20:27:48.000Z
- Description: AI adoption is accelerating faster than enterprise security controls can keep pace, with 94% of organizations increasing AI risk management spending as agentic AI, shadow AI, policy violations and security blind spots expand the attack surface.
- Author: Bill Brenner
- Tags: AI security spending, Agentic AI, Article

Organizations are pouring more money into AI security as rapid adoption exposes gaps in visibility, governance and the ability to control increasingly autonomous systems, according to new research from Omdia.

The September 2026 report, “[Security Risk Mitigation Strategies for Successful AI Adoption](https://www.ibm.com/products/guardium/guardium-exposure-manager?ref=cybrsecmedia.com),” surveyed 400 IT and cybersecurity professionals in North America responsible for security risk, compliance and evaluating or purchasing AI security products. The survey was conducted in May. 

The findings suggest organizations are trying to secure AI while adoption is already well underway. Ninety-seven percent allow employees to use public generative AI models, while 59% said publicly available models support the majority of their GenAI initiatives. 

That adoption is increasingly showing up in organizations' risk calculations. Sixty-four percent said AI has increased their overall risk profile. Organizations cited data management, securing AI embedded in approved applications, attacks against AI, privacy and ethical concerns, data resilience, regulatory compliance and visibility into AI usage among their challenges. 

[Subscribe to the CYBR.SEC.Media newsletter](#/portal/signup/free)

Agentic AI is adding another layer to the problem. The report found that 94% of respondents identified at least one challenge or concern related to managing the security risks of agentic AI. Data management led the list at 45%, followed by securing AI in approved applications at 42%, possible attacks on AI at 37%, ethical and privacy concerns at 38%, and data resilience at 37%. 

## Employees are finding ways around AI policies

Organizations are attempting to impose controls, but Omdia found little confidence that policies alone will keep AI usage within approved boundaries.

Only 11% of respondents said employees were “not at all likely” to violate security policies governing GenAI use. The remaining 89% acknowledged some possibility that employees could circumvent those policies, including 55% who said violations were either likely or very likely. 

Organizations are responding with a mixture of training and technical controls. Employee AI security training and monitoring AI systems for unintended or unpredictable behavior were the most commonly cited risk-mitigation approaches, at 34% each. Regular security audits followed at 27%, while 26% cited robust access controls and permissions. 

Formal governance is also taking shape. Forty-one percent said they already have a documented AI risk management framework, while another 49% are developing one. 

But implementation of specific guardrails remains uneven. The report's page 11 chart shows 48% regularly audit AI systems and processes, 47% monitor and log AI activity, and 42% scan AI models and large language models for vulnerabilities. Only 32% use automated anomaly detection for AI behavior, while 29% conduct pre-deployment testing and validation. 

## AI security incidents hit nearly four in five organizations

The spending push is occurring against a backdrop of reported security incidents.

Seventy-nine percent of organizations said they had experienced a cybersecurity incident involving AI threats during the previous 12 months. Data privacy violations were the most frequently cited cause at 31%, followed by AI introducing or exploiting application or infrastructure vulnerabilities at 28%. Integration and compliance risks each accounted for 25%, while unauthorized access and lack of human oversight were each cited by 23%. 

The consequences were significant. Among the 315 respondents reporting impacts from AI-related incidents, 43% experienced data loss, 37% reported unauthorized access to applications and data, 34% encountered malware and 27% reported ransomware. 

Those experiences appear to be feeding investment. Ninety-four percent of organizations expect spending on AI risk management solutions to rise over the next 12 to 18 months: 32% expect a significant increase and 62% expect spending to increase slightly. 

AI threat detection and monitoring tops the investment list at 40%, followed by employee AI security training at 32%, securing training and fine-tuning datasets at 30%, and gaining full visibility into AI use across the organization at 29%. 

## Security teams still face an AI visibility problem

The report also points to an organizational problem: Security teams don't always control — or even see — the AI technologies being deployed.

Forty-four percent of respondents agreed to some degree that involvement by separate groups such as IT and operations can leave security visibility or coverage gaps. Another 58% agreed that other groups may purchase or use security capabilities within AI tools without notifying security teams. 

That helps explain the demand for a new generation of AI security technology. Eighty-nine percent of respondents agreed that their organization is looking for solutions that give security teams more control over AI usage. Eighty-eight percent expressed interest in tools that use agentic AI to automate security tasks, while 87% said they are looking for new security tools built specifically for AI. Eighty-six percent want full visibility into both shadow AI and AI running inside approved applications. 

The message running through the Omdia findings is that enterprises aren't waiting for AI risk to be solved before adopting the technology. They're deploying AI now and trying to build the security controls around it at the same time.

As the report concludes, that makes policies and guardrails increasingly important, particularly as organizations move from GenAI assistants toward autonomous agents capable of taking actions on their own. Training humans is only part of the equation; organizations must also be able to monitor non-human actors for unintended behavior.

![](https://storage.ghost.io/c/ab/67/ab676516-71e3-473d-8f73-9e0692f5aaee/content/images/2026/10/2027-Events-Banner-3.png)